CVE-2021-38372: Command Injection
Published Aug 10, 2021
·Updated
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.
Affected Software
1 affected component
KDE Trojita=0.7
Event History
Aug 10, 2021
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-38372?
CVE-2021-38372 is a vulnerability in KDE Trojita 0.7 where man-in-the-middle attackers can create new folders due to untagged responses from an IMAP server being accepted before STARTTLS.
2
How severe is CVE-2021-38372?
CVE-2021-38372 has a severity rating of 3.7, which is considered medium.
3
How does CVE-2021-38372 affect KDE Trojita?
CVE-2021-38372 affects KDE Trojita 0.7, allowing man-in-the-middle attackers to create new folders.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-38372?
The CWE ID for CVE-2021-38372 is CWE-77.
5
Are there any references for CVE-2021-38372?
Yes, the following references provide more information on CVE-2021-38372: [Link 1](https://bugs.kde.org/show_bug.cgi?id=432353), [Link 2](https://nostarttls.secvuln.info).